Skip to main content
Emerging Threats

SonicWall Zero-Days Exploited in Wild, Firm Urges Immediate Patching

Industrial network device on a workbench surrounded by tools.

CVE-2026-83548 carries a CVSS score of 10.0 — the highest possible severity rating — and SonicWall says the flaw can be triggered without authentication.

Two linked zero-days: pre-auth SSRF and post-auth RCE

On September 1, SonicWall published a security advisory notifying customers that two zero-day vulnerabilities in SMA1000 appliances are being actively exploited in the wild. The vendor described the more critical flaw as CVE-2026-83548, a pre-authentication server-side request forgery (SSRF) in the SMA1000 Appliance Work Place interface. According to the advisory, the SSRF exists due to an "unintended alternate access path." SonicWall warned that "a remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations."

The second issue is CVE-2026-83549, a post-authentication remote code execution (RCE) vulnerability in the SMA1000 Appliance Management Console. SonicWall characterizes that bug as a "post-authentication improper neutralization of special elements used in an OS command" which, "in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution." CVE-2026-83549 carries a CVSS score of 7.8.

Affected models and software versions

SonicWall said the vulnerabilities affect SMA1000 appliances, naming models 6210, 7210 and 8200v. Impacted software builds are 12.4.3-03453 (platform-hotfix) and older, and 12.5.0-02835 (platform-hotfix) and older. The vendor’s advisory frames these appliances as gateway devices designed to enable remote workers to securely connect to corporate networks.

SonicWall’s remediation guidance

  • Upgrade to the latest hotfix version.
  • Contact SonicWall Technical Support for assistance in looking for indicators of compromise (IoCs).
  • If IoCs are detected on the system: re-image hardware or re-deploy appliances, change all user and admin passwords, and reset TOTP tokens.

SonicWall urged customers to take action whether they are running virtual or physical SMA1000 appliances.

Why SMA1000 edge appliances draw high-value attackers

The advisory notes that SMA1000 appliances are popular targets for state-sponsored and ransomware actors because, as edge devices, they provide remote access to sensitive corporate resources. Security agencies regularly warn of threats to edge devices; SonicWall’s advisory recalls that Five Eyes agencies published guidance for manufacturers of edge devices in February 2025 aimed at improving baseline security.

What this means for technologists, procurement leaders, and security teams

  • Technologists and security engineers: Prioritize immediate inventory and patching. The SSRF (CVE-2026-83548) is exploitable without authentication and holds a CVSS score of 10.0, which elevates urgency for vulnerable appliances running the named builds. Follow SonicWall’s upgrade path to the latest hotfix and engage Technical Support to hunt for IoCs.
  • Procurement and operations leaders: Confirm which SMA1000 models and builds are in use across the estate (6210, 7210, 8200v; 12.4.3-03453 and older; 12.5.0-02835 and older) and plan for expedited patch windows for both virtual and physical appliances.
  • Security teams and incident responders: If IoCs are found, SonicWall’s remediation checklist is explicit — re-image or redeploy appliances, change all user and admin passwords, and reset TOTP tokens. Treat any evidence of exploitation as requiring full remediation steps rather than simple incremental fixes.

SonicWall’s advisory, published on September 1, frames the situation simply and urgently: two actively exploited zero-days, one of them exploitable without authentication and rated at maximum severity, affecting edge gateways that control remote access to corporate networks. The vendor’s guidance leaves little room for delay — upgrade, hunt for compromise indicators with vendor support, and, where compromise is confirmed, re-image and reset credentials and tokens.

Read the original advisory and reporting: https://www.infosecurity-magazine.com/news/hackers-chain-sonicwall-zeroday/